Malicious PDF — malware analysis report

Static analysis result for SHA-256 1fcf07ff5fd5e9a5…

MALICIOUS

PDF

62.3 KB Created: 2021-06-11 07:23:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-26
MD5: 990174722b44404bd4bd8f51f35d8089 SHA-1: 633608b228f04a86f25c059cde25679517b0b18f SHA-256: 1fcf07ff5fd5e9a57556dee7f13249531d295cfad3174bd86e7f2ec736108c2e
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF file was detected as malicious by ClamAV and an ML classifier. It contains numerous links to external websites, many hosted on compromised WordPress sites, suggesting a link farm or phishing lure. The document body, though heavily obfuscated, contains references to 'Mxq pro firmware', indicating a potential lure for users seeking device updates. The presence of embedded URLs and the overall structure point towards a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6845

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
    PDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://medvor.ru/uplcv?utm_term=mxq+pro%252B+firmware PDF link annotation
    • https://teenvolunteerdallas.org/wp-content/plugins/super-forms/uploads/php/files/cbef9629fd0c6c92b48a716c61f81ab9/301505497.pdfIn PDF document text
    • https://event-connections.net/wp-content/plugins/formcraft/file-upload/server/content/files/1609845c3d1177---fonipu.pdfIn PDF document text
    • https://bindazzled.com.au/wp-content/plugins/super-forms/uploads/php/files/5b33908d25d773666fe0b2aba819025b/rinexa.pdfIn PDF document text
    • http://lycee-elm.org/userfiles/file/nadiv.pdfIn PDF document text
    • https://mindweave.co.uk/wp-content/plugins/super-forms/uploads/php/files/elsfaj3egmhvkqoenijrubqnbb/kulamuxijasetemesafimidek.pdfIn PDF document text
    • http://zrdb-drogbud.pl/Upload/file/70215281752.pdfIn PDF document text
    • https://amartzon.store/wp-content/plugins/super-forms/uploads/php/files/82421bf57a1d972f1bcce298e1b0dd96/gazonijabofu.pdfIn PDF document text
    • https://www.isgs.org/wp-content/plugins/super-forms/uploads/php/files/cda9e1b8f80fd6fbd847cf96ca0b6d4c/balanubufepebaxepusego.pdfIn PDF document text
    • http://titadoorbinhduong.com/upload/files/63009780803.pdfIn PDF document text
    • https://www.sabiamente.es/wp-content/plugins/formcraft/file-upload/server/content/files/1609d2eca78ada---lufuxafirofuloka.pdfIn PDF document text
    • https://ecomassage.pt/wp-content/plugins/super-forms/uploads/php/files/bnfjjmt3ciqiltvk51vtb1c2du/94783596334.pdfIn PDF document text
    • http://novichiha.ru/pic/file/siroda.pdfIn PDF document text
    • https://saftanton.dk/wp-content/plugins/formcraft/file-upload/server/content/files/1608e11cac3a79---48980857116.pdfIn PDF document text
    • https://nceptionsolutions.com/wp-content/plugins/super-forms/uploads/php/files/b7b77805588120e1e3601b1cb75485f0/zuzoxekuwitasu.pdfIn PDF document text
    • http://hayatteknoloji.com/webimage/file/38547919302.pdfIn PDF document text
    • https://www.modianodesign.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607c9b9468133---94044783511.pdfIn PDF document text
    • https://aartipalette.com/userfiles/file/fezavufivid.pdfIn PDF document text